Learn how to verify webhook requests to ensure they're coming from Linkkit.
With signature verification, you can determine if the webhook came from Linkkit, and has not been tampered with in transit.
All webhooks are delivered with a Linkkit-Signature header. Linkkit generates this header using a secret key that only you and Linkkit know.
An example header looks like this:
Linkkit-Signature: c9ed6a2abf93f59d761eea69908d8de00f4437b5b6d7cd8b9bf5719cbe61bf46
Finding your webhook's signing secret
You can find your webhook's signing secret in the Update Details tab:
Webhook signing secret — replace this callout with your screenshot in the CMS.
Make sure to keep this secret safe by only storing it in a secure environment variable (e.g. DUB_WEBHOOK_SECRET). Do not commit it to git or add it in any client-side code.
Verifying a webhook request
To verify, you can use the secret key to generate your own signature for each webhook. If both signatures match then you can be sure that a received event came from Linkkit.
The steps required are:
Get the raw body of the request.
Extract the signature from the Linkkit-Signature header.
Calculate the HMAC of the raw body using the SHA-256 hash function and the secret.
Compare the calculated HMAC with the one sent in the Linkkit-Signature header. If they match, the webhook is verified.
Here's an example of how you can verify a webhook request in different languages:
Why is signature verification important?
Signature verification is a crucial security measure that protects against request forgery and data tampering. Without verification, malicious actors could send fake webhook events to your endpoint, potentially triggering unauthorized actions.
The HMAC-SHA256 signature verification process ensures that only Linkkit can generate valid webhook requests and that payloads haven't been modified in transit. This provides both authentication (confirming the sender is Linkkit) and integrity (ensuring the message hasn't been tampered with).
Open the Linkkit dashboard to try these steps in your workspace.
